---
id: CVE-2025-13574
title: A weakness has been identified in code-projects Online Bidding System 1.0
summary: >-
  A weakness has been identified in code-projects Online Bidding System 1.0.
  This issue affects the function categoryadd of the file
  /administrator/addcategory.php. This manipulation of the argument catimage
  causes unrestricted upload. The…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
  - CWE-434
vendor: fabian
product: online_bidding_system
affected:
  - online_bidding_system = 1.0
published: '2025-11-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13574'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/Yohane-Mashiro/cve/blob/main/upload%201.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.333338'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333338'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.698717'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.698718'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00393
epssPercentile: 0.31379
ingestedAt: '2026-10-08T10:28:21.272Z'
---

## Overview

A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

## Affected

- `online_bidding_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
